Operationalizing Security Technology for Maximum Impact

In this installment of the “Real Words or Buzzwords?” series, operationalizing security technology takes center stage as the key to turning individual functions into adaptable, dependable organizational security capabilities.

Key Highlights

  • Operationalization turns configured security technologies into dependable organizational capabilities.

  • Integration and orchestration can coordinate technologies, people and processes toward defined security objectives.

  • AI-enabled technologies can help shift situational awareness from reactive response toward proactive prevention and intervention.

(Editor’s note: This is an installment of “Real Words or Buzzwords?” series about how real words become empty words and stifle technology progress.)

Operationalizing technology is not another term for configuring it. Configuration makes individual technologies function as intended. Operationalization establishes the people, processes, information, management practices, and other operational elements needed to put technology functions to purposeful and dependable use as part of an organizational security capability.

Designing for maximum capabilities

A physical security planning and design holdover from earlier eras is to plan a project where all capabilities are to be realized in a single, quick-as-possible deployment. Given the greatly expanded capabilities of modern technology, physical security technology deployment can be approached through three specific design objectives, implemented either as sequential phases of a single project or as deliberately planned stages.

However, staged deployment should not mean staged thinking. All three objectives can and should be considered from the beginning even when their implementation is deliberately spread over time. Failing to do so can result in needless rework or early design decisions that unnecessarily limit later capabilities.

First — Basic/Common Functions. Establish and operationalize the device or platform capabilities required for its basic or commonly intended purposes. This provides immediate security risk reduction improvements while also establishing the foundational familiarity personnel need with the basic operation of the technology.

Second — Advanced Functions. Establish and operationalize advanced capabilities that extend the technology's contribution to security operations—such as AI-enabled analytics, automated detection, or decision-support functions. This involves purposefully tuning the capabilities to match site-specific and personnel-specific needs, which can now be done more effectively and efficiently based on the technology familiarity gained initially. This is where security scenario-based prevention, detection, intervention, and response capabilities come into play. At this point, much more of the potential value of the individual technologies can be realized.

Third — Systems-of-Systems Integration and Orchestration. Establish and operationalize the technology's participation in the broader physical security system of systems, where information and functions from multiple technologies are coordinated to create adaptable and dependable organizational security capabilities. At this level, the focus shifts from what each individual technology can do to what the combined technologies can enable the organization to do.

Integration enables the technologies to exchange information and invoke functions across system boundaries. Orchestration coordinates those functions and information toward defined security purposes, enabling capabilities greater than those provided by the individual technologies acting alone.

shironosov / iStock / Getty Images Plus via Getty Images
AI delivers the greatest value when it helps security teams make sense of information, communicate shared understanding and translate decisions into consistent action.

From integration to orchestration

Physical security has been integrating technologies for decades, but integration by itself doesn't fully describe what today's systems-of-systems technologies can accomplish. Orchestration goes beyond connecting technologies and exchanging information by coordinating their capabilities toward defined security purposes.

Data centers are now a rapidly growing pillar of national infrastructure. Applying lessons learned from past experience, designers of new AI-centric data center facilities are establishing multilayered, highly resilient cyber and physical protections designed to work in tandem against blended cyber-physical threats. The same systems-of-systems security thinking is increasingly applicable to manufacturing and other industries whose operations and assets are critical to business and society.

The recent book, Data Center Security: The Blueprint for Resilient Infrastructure (available on Amazon), by Chris Hills, Program Manager, North America | Architects, Consultants & Engineers at Brivo, provides an excellent systems-of-systems perspective on this new territory. Hills describes the challenge this way: “Leadership in this context is about orchestration. It is about ensuring that the myriad teams responsible for physical plant, IT operations, cloud services, compliance, and emergency response operate not in silos, but as an orchestra with a shared score. The conductor’s task is not to play every instrument, but to ensure that each contributes to the symphony of resilience.” Throughout the book, Hills grounds the concepts of integration and orchestration in detailed real-world examples that show how they are put to work in establishing organizational security capabilities.

This is an important expansion of how we have traditionally thought about physical security systems integration. Integration connects technologies and enables them to exchange information and invoke functions across system boundaries. Orchestration coordinates the contributions of technologies, people and processes toward defined security purposes. Effective orchestration makes those coordinated capabilities both adaptable and dependable.

From rigidity to adaptability

For decades, much of physical security dependability was achieved through rigidity. We strengthened security by hardening successive physical layers — site perimeters, building perimeters, interior boundaries and protected spaces — and maintaining their integrity. Detection identified attempted or successful penetration of those layers, while people and processes filled the prevention and detection gaps. These protections remain essential, but they are no longer the limits of what physical security can accomplish.

Traditional situational awareness was also largely reactive. Something happened, a sensor generated an alarm or a person observed something, and security personnel worked to determine what was occurring quickly enough to respond. When threats changed, strengthening security often meant adding barriers, sensors, cameras, personnel, procedures or additional layers.

From reactive to proactive situational awareness

Today’s technologies enable a very different level of capability. AI-enabled sensing and analysis can help identify the development of a threat situation rather than merely detect the resulting security event. Information from multiple systems can provide context, support human decision-making, and enable proactive prevention, intervention and response. The physical layers remain essential, but adaptable capabilities can now operate across and around them.

This changes the meaning of situational awareness. Instead of simply catching up with events already underway, physical security can increasingly recognize developing conditions early enough to influence their outcome. Systems-of-systems orchestration can bring together sensing, analysis, context, communications, human judgment and appropriate automated actions according to the situation at hand.

The technology is here now

None of this requires waiting for the next generation of physical security technology. The technologies needed to establish adaptable, orchestrated security capabilities are available today. Nor does future-readiness require predicting what tomorrow’s technologies will be. It requires thinking and planning that are adaptable enough to incorporate emerging technologies when they fit evolving security needs.

From technology functions to organizational capabilities

That is why operationalization matters. Installing and configuring technology establishes what the technology can do. Operationalizing it establishes what the organization can dependably do with it. As technologies become more capable, interconnected and intelligent, the difference between those two things becomes increasingly important.

A security technology implementation is not complete until it produces the information needed to manage the capability it provides and makes that management easy. Operational readiness establishes the ability to use the capability. Management readiness establishes the ability to manage it. Assured infrastructure service establishes the ability to depend on it over time.

The opportunity is ours

The opportunity is not simply to deploy more advanced technology. It is to establish stronger organizational security capabilities by more fully operationalizing the technologies already available to us, while designing for the capabilities that integration, orchestration and emerging technologies can provide.

The only real limitation now isn’t in the tools — it’s in how we think.

About the Author

Ray Bernard, PSP, CHS-III

Ray Bernard, PSP, CHS-III

Ray Bernard, PSP, CHS-III, is the principal consultant for Ray Bernard Consulting Services (RBCS), a firm that provides security consulting services for public and private facilities (www.go-rbcs.com). In 2018 IFSEC Global listed Ray as #12 in the world’s top 30 Security Thought Leaders. He is the author of the Elsevier book Security Technology Convergence Insights available on Amazon. Ray has recently released an insightful downloadable eBook titled, Future-Ready Network Design for Physical Security Systems, available in English and Spanish.

Follow him on LinkedIn: www.linkedin.com/in/raybernard

Follow him on Twitter: @RayBernardRBCS.

Sign up for our eNewsletters
Get the latest news and updates